Introduction
Being ready to acquire and utilize evidence might serve as deterrence as well. Internal crime accounts for a significant portion of all crime. Employees will be aware of the organization's stance on organizational system policing. They will be aware of, or receive rumors about, the kind of offenses that might have being effectively or unsuccessfully committed, as well as the actions undertaken against employees. Preventive and detecting techniques are frequently the core of information security. There is minimal need for digital evidence in terms of information security prevention. Yet, there have been a variety of circumstances when gathering adequate digital evidence may be useful from a commercial standpoint. As a result, having digital proof available even before an event happens is a corporate requisite. This requirement's specific nature, whether it's satisfied, and how businesses might use digital evidence have never been thoroughly examined.
When building a digital forensics capacity, clear and explicit regulations are required because of legal constraints. When it comes to unlawful actions, policy must be followed in order for inquiries to stand up in court. The company might waste a lot of time and money if it doesn't have the right policies and processes in place. Even if criminal conduct isn't a threat, federal rules sometimes require that specific industries adhere to a set of rules. One of the most important aspects of developing a digital forensics competence should be tool usage guidelines. The NIST Guidelines to Incorporating Forensic Techniques into Incident Response explains why certain tools should be used in certain situations. “While the technologies offer numerous advantages, they may also be used to enable illegal access to information, modify or destroy information, including proof of an occurrence, either mistakenly or maliciously." The authorization of people for certain equipment should be specified in tool usage guidelines ,data Network administrators, help desk staff, and forensics professionals must not all have use to same surveillance devices. The findings must be credible and non-prejudicial in order for forensics inquiry findings to be acceptable. The technician's study must include all phases of a digital forensic inquiry. “Information is quickly shifting to an electronic form in which all information assets exist." It is becoming more vital in both the public and private sectors to establish decisively the authenticity, credibility, and dependability of digital records, like the execution of a specific act or judgment, or the presence of a specific piece of material.
Need for policy and procedure for digital forensics
Due to the expanding nature and complexities of contemporary cybercrime, as well as the increased usage of computers and digital assets in real-world crimes, digital forensics is a difficult and vital topic. Nearly each computer user is concerned about being a victim of cybercrime. As a result, cybercrime is a difficult challenge that can result in huge monetary loss. In particular, cyber criminals end up leaving evidence, which forensic investigators coincide and analyses to determine who, what, how, when a crime was dedicated. Forensic finding must be legally valid, genuine, comprehensive, credible, and plausible in order for the legitimate system to penalize criminals.
Anti-forensics techniques, on the other hand, have recently obtained popularity among lawbreakers who want to impede with forensic procedures by ruining digital proofs using various methods and tools.
The formalization of a framework for digital forensics may have a number of advantages that could be categorized as follows:
• Procedural: By lowering the amount of information and how it is managed;
• Technical: By letting digital forensic investigations to also be amended to for technical advancements;
• Social: An attack's abilities are captured in both the sociotechnical dimensions, and lastly;
• Legal: It enables the utterance of regulatory obligations during an inquiry.
To achieve the objective of digital forensics, various procedures have been suggested, but none has been globally acknowledged as the standard practice. Such procedures typically begin with data collection and finish with findings reporting. According to current studies, all of them provide examination and analysis stages in which cyber-attack artifacts must be recognized and reviewed. The above phases are critical not just since they are shared by all digital forensics procedures, but also since they are where the real investigation is underway.
The Systematic Digital Forensic Investigation Model (SRDFIM) concentrates on cyber—crime and cyber--fraud investigations. SRDFIM recommends data filtration, verification, pattern recognition, searching methods, rebounding ASCII and non-ASCII info, discovering strange hidden files or folders file extension and sign mismatches, etc. for the examination phase. The analysis stage is a technological investigation of the data obtained and derived from the examination step in order to recognize patterns and interactions in data, evaluate its importance, re - create events, and make conclusions.
The Integrated Digital Forensics Process Model (IDFPM) proposes a 4 step model to assist forensic experts in taking a consistent strategy to cyber-attack investigations. It is divided into four phases: "Preparation," "Incident," "Digital Forensics Investigation," and "Presentation." The investigation focuses on obtaining secret, obscured, removed, or noticeable electronic evidence/data and converting into a human easy to read format. The goal of the assessment is to find info that is pertinent to the case/hypothesis.
The Cyber Forensic Field Triage Process Model (CFFTPM) proposes a method for quickly recognizing, analyzing, and evaluating digital evidence. It focuses on reducing the time required to start investigating a felony at the scene, which is regarded as a critical factor. “Planning, triage, usage/user profiles, chronology/timeline, Internet activity, and case specific evidence are among the phases. Usage/user profiles, chronology/timeline, and Internet activity are the phases that are relevant to our work”. Even though this appears to be an artifact classification, this is not clearly outlined, and it is a task pertinent to SANS work.
The National Institute of Standards and Technology (NIST) define a strong digital forensics procedure as consisting of the following stages:
● Collection, with the goal of identifying and labeling any possible data sources appropriate to the event. Following that, the data contained within these inputs must be obtained while maintaining the credibility of the inputs.
● examining the collected data from the Acquisition process and retrieving the data relevant to the event whereas safeguarding its integrity.
● Analysis entails learning the information gleaned from the investigation in order to answer the questions or decide that no or only an incomplete conclusion can be made.
● Reporting is the methodology of readying and conveying the inquiry's process, techniques, and toolkits, as well as the outcomes of the analysis stage.
Cyber kill chain
The Cyber Kill Chain (CKC) is an intelligence-driven model proposed by Lockheed Martin to be followed in the identification and prevention of cyber-attacks [6]. It adapts the United States military’s kill chain process to the digital era to describe the following phases the adversaries pass through to achieve their objectives The CKC model fulfills two functions. It may be used to gather relevant information such that defense abilities can be tailored to the actions an enemy takes, as well as to analyze breaches. The intrusion assessment, on the other hand, implies that the identification of a cyber-attack has been predicated on an IoC. Once an IoC is discovered, analysis must begin with the phase to which IoC belongs and work backwards to preceding stages, as it is presumed that they have been completed. As a result, it is clear that CKC and IoCs can be utilized in conjunction in an inquiry if there is previous information of a cyber-attack.
CONCLUSION
The procedure of discovering, gathering, obtaining, conserving, evaluating, and delivering digital evidence is known as digital forensics. To be admissible in a court, digitized evidence should be verified. The forensic artifacts and methods used (e.g., stationary or live collection) are determined solely by the device, its operating systems, and its security mechanisms. Digital forensics is hampered by proprietary operating systems & safety measures (such as encryption). Encryption, which prevents 3rd parties from obtaining customers' data and conversations, might, for instance, prohibit law enforcement agencies from obtaining data on digital devices.
You must be logged in to post a comment.